DefectDojo October 6th Changelog 🚀 This week, we've released a new update of DefectDojo Pro and Community Edition. Here are the highlights from v3.4.0. * 🧪 (Sandbox) - Sandbox Mode: a practice copy of DefectDojo Pro under /sandbox/, on its own database and preloaded with sample data, with Reset and Wipe for superusers. Nothing done in the sandbox reaches production. * 🤖 (AI Inventory) - A beta AI inventory: every scanned repository gets an inventory of its coding assistants, MCP servers, models, AI packages, AI service endpoints, agent skills, and provider keys. * 🔌 (Connectors) - New Microsoft Azure and Google Cloud asset connectors, and a new Kenna Security (Cisco Vulnerability Management) connector. * and much more! Check out the changelog here: https://bit.ly/47zB5eS
DefectDojo
Computer and Network Security
Austin, Texas 2,646 followers
DefectDojo is the open source vulnerability management platform that remediates at the speed of AI
About us
DefectDojo is the open source unified vulnerability management platform that remediates at the speed of AI. Built by practitioners to end security finding sprawl, DefectDojo aggregates findings from more than 500 security tools into a single system of action, then automatically deduplicates, enriches, and prioritizes them so teams remediate real risk instead of drowning in noise. Sensei, DefectDojo's AI, closes the loop from detection to remediation by scanning repositories and opening pull requests that fix vulnerabilities without leaving the platform. Security teams use DefectDojo to automate triage, enforce SLAs, and report on security posture and compliance across frameworks including SOC 2, PCI-DSS, and the EU Cyber Resilience Act. Born from the OWASP community, DefectDojo is trusted by organizations of every size, from individual practitioners running the free Community Edition to enterprises deploying DefectDojo Pro in the cloud, on-premises, or in air-gapped environments. Learn more at defectdojo.com.
- Website
-
https://www.defectdojo.com
External link for DefectDojo
- Industry
- Computer and Network Security
- Company size
- 11-50 employees
- Headquarters
- Austin, Texas
- Type
- Privately Held
- Founded
- 2014
- Specialties
- cybersecurity, vulnerability correlation, devsecops, vulnerability management, and ASPM
Employees at DefectDojo
Locations
-
Primary
Get directions
1515 E Cesar Chavez St
Suite 100 PMB 1061
Austin, Texas 78702, US
Updates
-
Claude's advanced cyber capabilities are locked for almost everyone. Anthropic just unlocked them for DefectDojo, and we're pointing them at defense. That means exploit development, red teaming, penetration testing and bug bounty work. Claude blocks that category by default, for everyone. After its Cyber Verification Program review, Anthropic turned it on for our team. Why it matters: AI is finding zero-days in every major OS and browser. Attackers will have that, and nobody vets them. Defenders were getting told no by their own AI halfway through proving a finding is real. Why us: open any DefectDojo test file and it reads like an attacker's notebook, because that's what 500+ scanners send us every day. Plenty of vendors say they work for defenders. Anthropic checked who we are and what we do, and verified it. The access is monitored and can be pulled the day we drift. We'd rather be held to account than handed a badge. Fight AI with AI. Our team just got cleared for the advanced stuff. Full story: https://lnkd.in/g_zZRgzP
-
-
DefectDojo reposted this
Claude's advanced cyber capabilities are locked for almost everyone. Anthropic just unlocked them for DefectDojo, and we're pointing them at defense. That means exploit development, red teaming, penetration testing and bug bounty work. Claude blocks that category by default, for everyone. After its Cyber Verification Program review, Anthropic turned it on for our team. Why it matters: AI is finding zero-days in every major OS and browser. Attackers will have that, and nobody vets them. Defenders were getting told no by their own AI halfway through proving a finding is real. Why us: open any DefectDojo test file and it reads like an attacker's notebook, because that's what 500+ scanners send us every day. Plenty of vendors say they work for defenders. Anthropic checked who we are and what we do, and verified it. The access is monitored and can be pulled the day we drift. We'd rather be held to account than handed a badge. Fight AI with AI. Our team just got cleared for the advanced stuff.
-
-
Every scanner tells you what's wrong. None of them decide what happens next. So a person does it. Review the Finding, judge the risk, find the owner, notify them, open the ticket, track it. Then do it again for the next thousand. With DefectDojo Pro, your team writes that decision down once. Triage Engine turns the rules you already follow into workflows that run on every Finding. Critical Findings get an owner, a Slack message, and a Jira ticket. Lower-severity Findings get tagged for weekly review. You can see everything the automation does. Simulation runs a Rule against real Findings without sending anything outside DefectDojo. Every Run is traced node by node, so if 400 Findings enter a filter and zero pass, you see where. Each Finding shows which Rule changed it. Rules make the routine calls so your team can make the hard ones. Read the post: https://bit.ly/4hqRu9V #DefectDojo #vulnerabilitymanagement #AppSec
-
DefectDojo September 29th Changelog 🚀 This week, we've released a new update of DefectDojo Pro and Community Edition. Here are the highlights from v3.3.300. * 🌐 (i18n) - The Pro UI is now multilingual, with 27 languages available including German, Japanese, French, Italian, Spanish, Dutch, Portuguese (Brazil), Russian, Hindi, Bengali, Marathi, Tamil, Telugu, Hebrew, Arabic, Persian, and Urdu. A new setting lets you choose the interface language. * 📍 (Locations) - Code to Cloud Locations arrive: container-image and connector-populated cloud-resource inventories, an image-to-repository link, and typed location items. Harbor and Trivy Operator connectors emit inventories, and the scanned image or resource is recorded on every finding. * 🤖 (Sensei) - Sensei and AI Agent Red Teaming reach general availability. * and much more! Check out the changelog here: https://bit.ly/4rB9VO5
-
Vulnerability management has been priced for enterprises. Whether you're a small team of 2 or have a security team that handles hundreds of developers, vendors do not price for your needs. They price for your size. Starting today, DefectDojo Pro is $100 a month plus 15 cents per finding processed. No seat count, no application count, no sales call. Sign up at cloud.defectdojo.com, connect your scanners, set a monthly spend limit, and pay for what you use. The $100 covers the full Pro feature set: cross-scanner deduplication, EPSS and CISA KEV enrichment, risk-based prioritization, the Triage Engine, Connectors, SSO and RBAC, SLA enforcement, and reporting an assessor will accept. Findings below your minimum severity are dropped before they are counted. Sensei is billed only when you use it: $15 for a remediation pull request, $30 for a threat model. Pre-pay for a year and save 48% or more. Why now? The models attackers will run next year find bugs faster than your team can read the reports. Fixing everything, quickly, should not depend on your headcount. Read the post: https://bit.ly/4jiPNhq
-
-
You have been lied to about security. Not by the attackers. By the people selling the fix. Charged to find your vulnerabilities. Charged again to see them. Charged a third time to prove you fixed them. That is not a partner. That is a landlord. Today DefectDojo flies a new flag. It is the same mission we've been fighting for the last 10 years but we are no longer just the platform that aggregates your findings, but the platform that identifies and fixes risk. But talk is cheap and seeing is believing. In the last month alone: Threat Intelligence, now generally available, with EPSS and CISA KEV built into prioritization. Reachability. AI Threat Modeling. CSPM. Vulnerability Explorer. Triage Engine. 500+ connectors and parsers. And Sensei, an AI agent that can triage, prioritize, and fix your vulnerabilities in minutes. Your findings are yours. Your data is yours. Your exit is always open. The full story from our CEO: https://buff.ly/7iKV9iP The dojo doors are open. Join the underground.
-
-
Security vendors have told you cybersecurity is difficult, expensive, and an endless struggle. They're wrong. The backlog doesn't have to be permanent. Security doesn't have to be a struggle. And your tools shouldn't hold your data hostage. Today, we expand the mission of DefectDojo and fight for all teams to bring their vulnerability backlog to zero. Join the underground
-
DefectDojo September 22nd Changelog 🚀 This week, we've released a new update of DefectDojo Pro and Community Edition. Here are the highlights from v3.3.200. 📜 (Compliance) - PCI DSS compliance pack: scope and scope inventory, patch-clock SLAs (6.3.3), targeted risk analyses (12.3.1), quarterly scan and ASV evidence, a vulnerability-management control catalog, and a PCI DSS evidence workbook. 📈 (Dashboards) The Command Center dashboard scene, now the home page for every user. 🎯 (Findings) EPSS and CISA KEV threat-intelligence fields are editable on the Add/Edit Finding form. and much more! Check out the changelog here: https://lnkd.in/e3GPTFKU